Description
Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.
Affected products
References
- MISChttp://securityvulns.ru/Rdocument843.html
- MISChttp://www.securityfocus.com/archive/1/477253/100/0/threaded
- MISChttp://www.securityfocus.com/bid/25391
- MISChttp://websecurity.com.ua/1159/
- MISChttp://osvdb.org/37097
- VENDOR_ADVISORYhttp://secunia.com/advisories/26560
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/36149